Home About Black Hat Contact Essays Fireside Chats My Take News Alerts Q&A Reels RSAC Videocasts ☰
 

Q & A

 

SHARED INTEL Q&A: AI finds flaws faster — defenders still need to fix what attackers exploit

By Byron V. Acohido

Security teams are being told they have hours to patch.

Related: AI agents have a Lord of the Flies problem

The warning has a real basis. In June, Anthropic’s frontier red team demonstrated an AI model building working exploits from freshly patched Firefox and Windows kernel vulnerabilities, one of them in 31 minutes. Meanwhile ZeroDayClock, widely cited across the security industry, put mean time-to-exploit near a single day and projected it falling to one hour by 2027.

Root Evidence went looking for evidence that attacker behavior had actually changed.

Its recently released Vulnpocalypse Report traced confirmed in-the-wild exploitation of published CVEs from January 2018 through July 15, 2026. Of 253,912 vulnerabilities published during that period, adversaries exploited 3,769, about 1.5 percent. For vulnerabilities exploited after a patch was available, the median defender window was 116 days so far in 2026, compared with 24 days in 2018.

BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate

By Byron V. Acohido

LAS VEGAS – Companies are deploying AI agents into everyday work at a pace no security program was built for.

Related: AI layoffs pays for AI infrastructure

As Black Hat USA 2026 gets underway in Las Vegas, that question is moving rapidly from theoretical concern to operational reality.The rush is competitive. Nobody wants to be the last one still doing this by hand. What’s getting skipped is the harder question: once an agent is acting on a company’s behalf, how does anyone know what it’s actually doing?

Companies are handing routine tasks to AI agents. Each one moves through the same screens a person would, and every check along the way comes back clean. The login names whose credential is in use. It says nothing about who, or what, is actually operating the account.

Identity systems answer one question well: who is logging in. Multifactor authentication and single sign-on are built for that, and only that. Nothing checks what the login is then allowed to do.

BLACK HAT Q&A: SBOM claims what went in, binary shows what shipped, the risk lies between

By Byron V. Acohido

LAS VEGAS – Almost every company can now produce a list of what’s inside its software. Almost none can prove the list is right.

Related: SBOM’s role in cybersecurity

Construction solved this a century ago. Every steel beam carries a stamp naming the mill that poured it. Every concrete truck arrives with a ticket recording the batch. Every fire door ships with a label certifying its rating.

Software has been catching up. Every open source library pulled into a build is supposed to be logged, every third-party component identified, every dependency traced to its source. The software bill of materials, or SBOM, is the sum of that accounting: one list of everything inside the finished product.

But that accounting assumes a clean starting point, and software almost never has one. An old build carries whatever it carried the day it was assembled, and every version after it inherits the load.

BLACK HAT AUTHOR Q&A: The adversary doesn’t care which department owns the data

By Byron V. Acohido

The line between physical security, cybersecurity, privacy and reputation management is dissolving. A data leak can surface a home address.

Related: Defending the CEO attack vector

A breached account can put an executive’s family in physical danger. The threats don’t stay in their lanes.

That’s the terrain Chuck Randolph, Jonathan Wackrow and Fred Burton map in The Protector’s Edge: Leadership Through Strategy and Action. Their argument: executive protection has outgrown the old picture of bodyguards, travel logistics and perimeter walls. Today’s protector has to read digital exposure, business continuity and reputation risk, and the pressures bearing down on the C-suite.

Doxxing, deepfakes, AI-enabled impersonation and online radicalization are forcing boards to rethink what protection means. CISOs, CSOs, legal, communications and privacy teams each watch a different dashboard. Adversaries see one target.

SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents

By Byron V. Acohido

As if keeping track of machine identities wasn’t hard enough.

AI agents are now arriving by the thousands — and most enterprises are just handing them borrowed credentials and hoping for the best.

Meanwhile, the cryptographic infrastructure asked to absorb these threats faces a hard regulatory countdown requiring digital certificates — the credentials securing every machine connection — to rotate eight times more often than they do today.

Related: Certificate expiration is speeding up

That same foundation now faces three converging demands at once: vouch for AI agents, authenticate synthetic media and survive the coming migration to quantum-safe cryptography — all on overlapping deadlines

SHARED INTEL Q&A: AI retrieval systems can still hallucinate; deterministic logic offers a fix

By Byron V. Acohido

AI hallucination is still the deal-breaker.

Related: Correcting LLM hallucinations 

As companies rush AI into production, executives face a basic constraint: you cannot automate a workflow if you cannot trust the output. A model that fabricates facts becomes a risk exposure. CISOs now have to explain this clearly to boards, who expect assurances that fabrication risk will be controlled, not hoped away.

Earlier this year, retrieval-augmented generation, or RAG, gained attention as a practical check on hallucination. The idea was straightforward: before answering, the model retrieves grounding material from a trusted source and uses that to shape its response. This improved reliability in many early use cases.

But first-generation RAG had a hidden weakness. A major academic study (“RAGTruth”) showed that even when RAG retrieves accurate source material, AI systems can still misstate it or draw the wrong conclusion. The research comes from the ACL Anthology, the leading global library for peer-reviewed AI language research.

AUTHOR Q&A: New techno-thriller ‘The Virus’ simulates an AI malware outbreak gone global

By Byron V. Acohido

Eddy Willems has been a steady, pragmatic voice in cybersecurity for decades — known for breaking down complex threats in ways real people can understand.

Related: AI fueling disinformaton

With The Virus, he tries something new: a fast-paced techno-thriller that fuses autobiography with speculative fiction. The result reads part memoir, part cautionary tale, part simulation of how a global cyber outbreak might unfold.

The story toggles between threat briefings and the fictional rise of “Doomware,” a novel virus that spirals from localized disruption into full-blown global crisis. Willems casts himself as a lightly fictionalized version of his real-life role, offering insight through scenes that draw on years of direct frontline experience.

In today’s threat landscape — shaped by AI acceleration, ransomware-as-a-service, and politicized disinformation — The Virus feels eerily plausible. Its fictional twists are anchored in real-world behaviors and known vulnerabilities. Because Willems never strays too far from facts, the book functions as both gripping story and subtle cybersecurity literacy. It doesn’t preach, but it lands with urgency.